IP Library Granted Patent US 10,798,081
Granted Patent B2
US 10,798,081 · App. 16/171,186 · Granted Oct 6, 2020

Method, apparatus, and system for providing a security check

Inventor: Jinggang Feng (Hangzhou, CN)
Assignee: Alibaba Group Holding Limited
H04L63/08G06Q20/3276G06Q20/388H04L9/3226H04L9/3297H04L63/0876H04L63/10H04L63/12H04W12/06H04W12/08H04L63/067H04L2209/34H04W12/00522
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,798,081
App. No.
16/171,186
Granted
Oct 6, 2020
Kind
B2
Abstract

Embodiments of the present application relate to a method, apparatus, and system for providing a security check. The method includes receiving a security verification request sent from a terminal, obtaining first verification element information based at least in part on the security verification request, generating a digital object unique identifier based at least in part on the first verification element information, sending the digital object unique identifier to the terminal, receiving second verification element information from the terminal, and in the event that the first verification element information and the second verification element information are consistent, sending security check pass information to the terminal.

Claims (49)

1. A method, comprising:

receiving, by a server, a security verification request sent from a terminal, the security verification request comprising an identifier associated with a user;

obtaining, by the server, an identifier associated with the terminal based at least in part on the identifier associated with the user, wherein the identifier associated with the terminal is obtained in connection with the receiving of the security verification request;

obtaining, by the server, first verification element information based at least in part on the security verification request, or the identifier associated with the terminal or the user of the terminal;

generating, by the server, a digital object identifier based at least in part on the first verification element information;

sending, by the server, the digital object identifier to the terminal;

receiving, by the server, second verification element information from the terminal, wherein the second verification element information is determined by the terminal based at least in part on information extracted by the terminal from the digital object identifier; and

authenticating the terminal in response to a determination that the first verification element information and the second verification element information match, and a determination that a second timestamp included in the second verification element information is within a predefined time limit of a security check associated with the security verification request.

2. The method of claim 1 , wherein the digital object identifier is a unique identifier.

3. The method of claim 1 , wherein the identifier associated with the terminal or a user of the terminal is comprised in the security verification request.

4. The method of claim 1 , wherein the authenticating of the terminal comprises granting to the terminal access to one or more network resources.

5. The method of claim 1 , wherein the second verification element information corresponds to information determined by the terminal from the digital object identifier, the determined information corresponding to the first verification element information.

6. The method of claim 1 , wherein the terminal obtains the second verification element information by processing the digital object identifier.

7. The method of claim 1 , further comprising:

determining whether the first verification element information and the second verification element information match.

8. The method of claim 1 , wherein the generating of the digital object identifier based at least in part on the first verification element information comprises:

generating a first combination character string by combining a first terminal identifier, a first security verification code, and a first timestamp associated with the security verification request, wherein the first security verification code is obtained based at least in part on the security verification request, and the identifier associated with the terminal or the user of the terminal, and

generating the digital object identifier based at least in part on the first combination character string.

9. The method of claim 1 , wherein the generating of the digital object identifier based at least in part on the first verification element information comprises:

generating an encrypted character string based at least in part on encrypting the first combination character string;

converting the encrypted character string to a base 64 character string;

encoding the base 64 character string according to a Quick Response (QR) encoding rule; and

generating a two-dimensional verification code, wherein the two-dimensional verification code corresponds to the digital object identifier.

10. The method of claim 1 , wherein the second verification element information is sent by the terminal in response to the terminal obtaining the identifier associated with the terminal from the digital object identifier, and determining that the identifier associated with the terminal obtained from the digital object identifier corresponds to the terminal.

11. The method of claim 1 , further comprising:

saving relationships among a first terminal identifier, a first security verification code, and a first timestamp, wherein the first terminal identifier is determined based at least in part on the identifier associated with the terminal or the user of the terminal, and the first security verification code is obtained based at least in part on the security verification request and the first timestamp,

wherein the second verification element information comprises: a second terminal identifier, a second security verification code, and the second timestamp that are obtained by decomposing a second combination character string, wherein the second combination character string is obtained by the terminal scanning the digital object identifier, and wherein the second verification element information corresponds to information sent from the terminal in response to a determination that the terminal has compared the second terminal identifier with the first terminal identifier of the terminal and determined the second terminal identifier and the first terminal identifier of the terminal match; and

wherein the authenticating the terminal comprises:

searching, based at least in part on the second terminal identifier, a plurality of relationships among a plurality of first terminal identifiers, a plurality of first security verification codes, and a plurality of first timestamps, and obtaining the security verification code and the timestamp respectively corresponding to the second terminal identifier; and

in response to a determination that the second security verification code and the obtained security verification code match, the second timestamp and the obtained timestamp match, and the second timestamp is within a time limit of a present security check associated with the security verification request, determining that the terminal is authenticated.

12. The method of claim 1 , wherein the second verification element information comprises the identifier associated with the terminal, and the second verification element information is sent to a server from the terminal.

13. A device, comprising:

at least one processor configured to:

receive a security verification request sent from a terminal, the security verification request comprising an identifier associated with a user;

obtain an identifier associated with the terminal based at least in part on the identifier associated with the user, wherein the identifier associated with the terminal is obtained in connection with the receiving of the security verification request;

obtain first verification element information based at least in part on the security verification request, or the identifier associated with the terminal or the user of the terminal;

generate a digital object identifier based at least in part on the first verification element information;

send the digital object identifier to the terminal;

receive second verification element information from the terminal, wherein the second verification element information is determined by the terminal based at least in part on information extracted by the terminal from the digital object identifier; and

authenticate the terminal in response to a determination that the first verification element information and the second verification element information match, and a determination that a second timestamp included in the second verification element information is within a predefined time limit of a security check associated with the security verification request; and

a memory coupled to the at least one processor and configured to provide the at least one processor with instructions.

14. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a security verification request sent from a terminal, the security verification request comprising an identifier associated with a user;

obtaining an identifier associated with the terminal based at least in part on the identifier associated with the user, wherein the identifier associated with the terminal is obtained in connection with the receiving of the security verification request;

obtaining first verification element information based at least in part on the security verification request, or the identifier associated with the terminal or the user of the terminal;

generating a digital object identifier based at least in part on the first verification element information;

sending the digital object identifier to the terminal;

receiving second verification element information from the terminal, wherein the second verification element information is determined by the terminal based at least in part on information extracted by the terminal from the digital object identifier; and

authenticating the terminal in response to a determination that the first verification element information and the second verification element information match, and a determination that a second timestamp included in the second verification element information is within a predefined time limit of a security check associated with the security verification request.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 054233/0693 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053667/0148 →
Priority Claims (1)
CN 2014 1 0219868 · May 22, 2014 · national
Continuity (3)
Continuation 15667262 · Aug 2, 2017
Continuation 14717545 · May 20, 2015
Related Publication 20190068571A1 · Feb 28, 2019